Disaster recovery, explained without the jargon
We end up explaining this on discovery calls often enough that it deserved writing down. Here is disaster recovery without the vocabulary that usually surrounds it.
Security is a maintenance habit rather than a purchase, which is why it drifts. The version that survives contact with a real deadline is the simple one.
The short version
Ask how long you could be down before it really hurts. This is the sort of thing that compounds, quietly, in both directions. Write the reasoning down alongside the decision, because the reasoning is what changes first.
Why people complicate it
Most of the confusion comes from tooling rather than from the idea itself. Where this goes wrong is almost never a lack of knowledge.
That answer sets your budget. Small and consistent beats large and occasional here. It rarely shows up as a line item, which is exactly why it slips.
A reasonable first step
Practise the recovery at least once a year. The teams that handle this well are rarely the ones with the biggest budgets. The version that survives contact with a real deadline is the simple one.
The short version
The cheapest security work is the boring kind done on a schedule. Three things worth confirming about disaster recovery before you move on:
- Someone can say what the current setup is without going to look
- Ask how long you could be down before it really hurts — and you know whether that is true here
- There is a way to tell whether the last change to this helped
If you want a second opinion on how yours is set up, ask.